CVE · Medium

CVE-2022-0683 — Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.0.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-0683 Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.0.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 5.0.9 5.0.9 2022-02-18

CVE-2022-0683

The Essential Addons for Elementor Lite plugin before version 5.0.9 contains a cross-site scripting vulnerability in the Helper.php file where the settings parameter lacks proper escaping and sanitization. An attacker can exploit this flaw by crafting a malicious link that injects arbitrary JavaScript code, which executes when users click the link. This vulnerability impacts all versions up to and including 5.0.8.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.